<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>RC F&#39;13, F2&#39;17&#xA;Cryptogopher / Go cryptography maintainer&#xA;Professional open source maintainer&#xA;https://filippo.io / https://github.com/FiloSottile&#xA;https://mkcert.dev / https://age-encryption.org&#xA;https://sunlight.dev / https://filippo.io/newsletter</description><link>https://blacksky.community/profile/filippo.abyssdomain.expert</link><title>@filippo.abyssdomain.expert - Filippo Valsorda</title><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mko6wxtwok2f</link><description>Copy Fail? Also looks like memory safety, but is actually complexity.&#xA;&#xA;https://xint.io/blog/copy-fail-linux-distributions#how-this-happened-3&#xA;&#xA;I am going to link to this while rejecting changes to Go crypto for years.&#xA;&#xA;Anyway, feeling pretty validated in my &#34;ssh in as root, only gVisor or Firecracker are an actual security boundary&#34; approach.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>29 Apr 2026 22:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mko6wxtwok2f</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mklctioas224</link><description>… are fucking kidding me.&#xA;&#xA;A github.com cross-account RCE due to the most pedestrian of injection attacks along the obvious exposed surface… and they actually have a globally shared “git” UNIX user!!&#xA;&#xA;This is not what taking the role of supply chain stewards seriously looks like.&#xA;https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</description><pubDate>28 Apr 2026 19:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mklctioas224</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mkkmc7ljk22g</link><description>Looks like GitHub silently corrupted some index.&#xA;&#xA;PR #237 definitely exists and is closed (https://github.com/C2SP/C2SP/pull/237) but is just... not in the list (https://github.com/C2SP/C2SP/pulls?q=is%3Apr+is%3Aclosed) regardless of filters.&#xA;&#xA;I briefly doubted my own sanity. This is bad.</description><pubDate>28 Apr 2026 12:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mkkmc7ljk22g</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mkjcgzaums2i</link><description>Damn, that felt good.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>28 Apr 2026 00:13 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mkjcgzaums2i</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mkjbzbzxh62b</link><description>A bit over two years after starting to work on it...&#xA;&#xA;Go is officially FIPS 140-3 certified 💥 &#xA;&#xA;https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5247&#xA;&#xA;I am pretty confident Go is now one of the most—if not the most—seamless and complete FIPS 140-3 compliance solutions... with a single env var, out of the box.</description><pubDate>28 Apr 2026 00:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mkjbzbzxh62b</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mkaolhmegk2i</link><description>I think it&#39;s important to triage failed predictions and I was wrong about this one.&#xA;&#xA;It looks like it&#39;s more organizational dysfunction and neglect than the &#34;embrace, extend, extinguish&#34; I was told to be worried about but the acquisition did not work out well for GitHub.&#xA;&#xA;https://xcancel.com/FiloSottile/status/1003455011605700608&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>24 Apr 2026 13:56 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mkaolhmegk2i</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mk65ca4vbz2z</link><description>How much storage / bandwidth / CPU / memory does it take to run a production Sunlight CT log? Surprisingly little!&#xA;&#xA;There&#39;s now a public stats page, pulled every 5m from our Tuscolo prod metrics.&#xA;&#xA;stats.sunlight.geomys.org&#xA;&#xA;Less than 2 cores, 300 MB of memory, ~250 Mbps of bandwidth, 260 GiB of SSD.</description><pubDate>23 Apr 2026 13:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mk65ca4vbz2z</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mk47b6upec2h</link><description>Hey, if you think you&#39;re justified in being an anti-social ass to Why, could you block me?&#xA;&#xA;It&#39;s ok, no need to discuss it. I&#39;m not looking for a fight and we&#39;re not going to converge. I know you think you are justified by that very good reason. Good for you.</description><pubDate>22 Apr 2026 19:11 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mk47b6upec2h</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mk46o4b4ee2b</link><description>NIST is updating SP 800-133, which details the &#34;FIPS approved&#34; ways to generate keys.&#xA;&#xA;There&#39;s a lot of good news in it, it approves a lot of stuff we were doing, like X-Wing seed derivation and c2sp.org/det-keygen.&#xA;&#xA;Here are my comments: https://leaflet.pub/f6fc0b3b-161d-4e35-99cd-e95ad62402a5</description><pubDate>22 Apr 2026 19:01 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mk46o4b4ee2b</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjwv6s6kje2z</link><description>There are no technical or compliance reasons to double the size of symmetric keys in response to the threat of quantum computers.&#xA;&#xA;This common misunderstanding of Grover&#39;s algorithm risks wasting limited resources that should go towards deploying actually urgent post-quantum algorithms.&#xA;https://words.filippo.io/128-bits/</description><pubDate>20 Apr 2026 16:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjwv6s6kje2z</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjslnehbt224</link><description>It&#39;s April 2026, 1 year 8 months since FIPS 204.&#xA;&#xA;The IETF TLS WG is busy debating the concept of ML-DSA hybrids, and whether they should be composite, concatenated, or separate. The complexity of hybrid auth is, however, firmly denied.&#xA;&#xA;In the distance, sounds of a pure ML-DSA PKI being built.</description><pubDate>18 Apr 2026 23:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjslnehbt224</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjpqfq7vz227</link><pubDate>17 Apr 2026 20:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjpqfq7vz227</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjmf7irsn226</link><description>This is awesome! Great to see more full-time positions for open source maintainers funded by commercial retainers framed around sustainability.&#xA;&#xA;And uh... looks like Geomys might be undercharging!&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>16 Apr 2026 12:15 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjmf7irsn226</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjkwt2inss2x</link><description>YES! No more made up severity scores for most CVEs!&#xA;&#xA;Every OSS maintainer I know hated those. (It&#39;s basically impossible to give a score to the severity of a vulnerability in a widely used library. They can ~all be low or critical, depending on how they are used.)&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>15 Apr 2026 22:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjkwt2inss2x</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjkufwtwps27</link><description>I had a whole post on &#34;yes, HKDF is FIPS 140-3 compliant, actually&#34; but now NIST just went and added it by name to the list of Approved algorithms with a change comment saying &#34;it was always compliant, yo&#34; (paraphrased), so yay.&#xA;&#xA;words.filippo.io/fips-hkdf/</description><pubDate>15 Apr 2026 21:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjkufwtwps27</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjklsutb6s2j</link><description>There are only two bug classes left: complexity and memory safety.&#xA;&#xA;CurveBall (CVE-2020-0601)? Complexity.&#xA;BigSig (CVE-2021-43527)? Memory safety.&#xA;Log4Shell (CVE-2021-44228)? Complexity.&#xA;BlueKeep (CVE-2019-0708)? Memory safety.&#xA;&#xA;Heartbleed looks like memory safety, but it&#39;s actually complexity.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>15 Apr 2026 19:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjklsutb6s2j</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mjjwpkr3a226</link><description>I wrote up in the TLS mailing list why I think composite signatures (ML-DSA + ECDSA/RSA) are a net negative, will hurt the ecosystem, and should not be implemented.&#xA;&#xA;Hybrid key exchange was simple and self-contained. Hybrid signatures would be a mountain of complexity in delicate, critical code.&#xA;https://mailarchive.ietf.org/arch/msg/tls/oh3jmmkHzHdp1hk4R4M9QjkmvBk/</description><pubDate>15 Apr 2026 12:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mjjwpkr3a226</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mj7wo6py3s2u</link><description>ProTip: you can have multiple handles in your DID document!&#xA;&#xA;For example, you can see I am both @filippo.io and @filippo.abyssdomain.expert. https://pdsls.dev/at://did:plc:x2nsupeeo52oznrmplwapppl#identity&#xA;&#xA;@bsky.app uses the first, but also loads profile links for the others. https://bsky.app/profile/filippo.io&#xA;&#xA;@tangled.org lets you pick now!</description><pubDate>11 Apr 2026 13:23 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mj7wo6py3s2u</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mj6kl5y7vc2g</link><description>Alright, it&#39;s official! 💰&#xA;&#xA;@matthewdgreen.bsky.social and I bet on what will break first, ML-KEM-768 or X25519. The loser donates to a 501(c)(3) picked by the winner.&#xA;&#xA;If you have an opinion on quantum computers or lattices, you can join with a side bet. Just submit a PR!&#xA;&#xA;https://github.com/FiloSottile/ecc-vs-lattices-long-bet&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>11 Apr 2026 00:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mj6kl5y7vc2g</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mj5k6m6jxk2x</link><description>1. The Xteink X4 is so cute&#xA;&#xA;2. It&#39;s so cool you can just ask an LLM for a firmware feature&#xA;&#xA;3. To flash the community firmware, you just go to xteink.dve.al and click flash, thanks to WebUSB&#xA;&#xA;It&#39;s so sad Firefox doesn&#39;t implement WebUSB. Better UX *and* better security than downloading an exe.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>10 Apr 2026 14:34 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mj5k6m6jxk2x</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mj5bynjnzk2l</link><description>Come for the updated graph, stay for the very balanced and reasonable Outlook section, which matches and reinforces my risk assessment: it&#39;s unlikely we&#39;ll see a CRQC in 2030 but not unlikely enough. So we ship.&#xA;&#xA;https://sam-jaques.appspot.com/quantum_landscape_2026&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>10 Apr 2026 12:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mj5bynjnzk2l</guid></item><item><link>https://blacksky.community/profile/filippo.abyssdomain.expert/post/3mj3ab2yj2s2k</link><description>Can we talk about the fact that we can just tell the computer&#xA;&#xA;&gt; extract from 2026-04-08-17-15-58.mkv an audio file that is compatible with MacWhisper, ideally losslessly&#xA;&#xA;and it just runs ffmpeg for us now??</description><pubDate>09 Apr 2026 16:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:x2nsupeeo52oznrmplwapppl/app.bsky.feed.post/3mj3ab2yj2s2k</guid></item></channel></rss>